saleor-webhooks

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation from docs.saleor.io and retrieves public keys (jwks.json) from the configured Saleor instance domain for signature verification. These are standard operations for e-commerce integrations.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external data (webhook payloads). It includes strong mitigation guidance, explicitly requiring JWS or HMAC signature verification before any payload processing occurs to ensure data authenticity.
  • [COMMAND_EXECUTION]: The allowed-tools list includes Bash, which is common for developer-centric skills. No suspicious or automated shell commands are present in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM